Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
BID:68066
Info
Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 68066 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0598 |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2014 12:00AM |
| Updated: | Jun 20 2014 12:05AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Novell Open Enterprise Server 2 Linux Support Pack Novell Open Enterprise Server 2 Linux Support Pack |
| Not Vulnerable: | |
Discussion
Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
Novell Open Enterprise Server is prone to an unspecified directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Versions prior to May 2014 OES11SP1 Scheduled Maintenance Update 9151 are vulnerable.
Novell Open Enterprise Server is prone to an unspecified directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker could exploit this issue using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
Versions prior to May 2014 OES11SP1 Scheduled Maintenance Update 9151 are vulnerable.
Exploit / POC
Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Novell Open Enterprise Server CVE-2014-0598 Unspecified Directory Traversal Vulnerability
References:
References:
- Novell Homepage (Novell)